Privacy Policy

Last updated: July 2026

Vaxal Net Co., Ltd. (“Vaxal,” “we” or “us”) respects and protects your personal data. This policy is drafted in accordance with Taiwan’s Personal Data Protection Act (PDPA) and Google’s API services policies. It explains how we collect, process, use and protect your personal data when you use Ryxis (ryxis.ai), Ryxis Greenhouse (gh.ryxis.ai), FormalDoc and the vaxal.io website (together, the “Service”; this policy applies to all of those domains). By registering, signing in or using the Service, you are deemed to have read and agreed to this policy; this policy applies together with our Terms of Service.

Google API Services User Data Policy (Limited Use)

The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

1. Data controller and contact

Data controller: Vaxal Net Co., Ltd. (Vaxal).

Address: 7F, No. 218, Dunhua N. Rd., Songshan Dist., Taipei City, Taiwan.

Email: vaxalnet@gmail.com Phone: +886 950-750-511.

For any questions about this policy or your personal data, or to exercise the rights below, contact us using the details above.

2. Personal data we collect

Account and identity data: when you sign in with Google, we receive your name, email, avatar and Google account identifier to create and identify your account.

Content you provide: data you type, upload or create in the Service (e.g. Ryxis conversations, Greenhouse knowledge fragments, FormalDoc documents).

Usage and technical logs: registration and sign-in times, IP address, browser and device information, activity logs and cookies.

Third-party (Google) service data you authorize: obtained only when you explicitly enable the corresponding feature (see section 4).

3. Purposes of collection and use

We collect and use your personal data to: provide, operate and improve the Service; create accounts and verify identity; manage subscriptions and billing; send account notices and provide customer support; manage information and databases; and comply with law or competent authorities.

4. Google OAuth and Google APIs (YouTube, Calendar)

We use Google OAuth 2.0 for user authentication. When you sign in with Google, we obtain your basic profile to create and identify your account.

Accounts and authorization are centralized at Vaxal: the Service uses single sign-on (SSO). You create one Vaxal account at vaxal.io and use it to sign in to products such as Ryxis (ryxis.ai) and Ryxis Greenhouse (gh.ryxis.ai). All Google sign-in and authorization — including the consent screens for the features below — is handled centrally by the single sign-on service at vaxal.io, which is why the Google consent screen shows the name Vaxal. The features described below run in Ryxis Greenhouse (gh.ryxis.ai) and are used with that same Vaxal account.

We access data within the scope you authorize, through the relevant Google APIs, only when you explicitly enable the corresponding feature, and use it solely to provide that feature:

YouTube (YouTube Data API, read-only): when you use the “run your apps on your live stream” feature, we read only the channel ID and channel title of the account you authorize, in order to confirm that the live channel you want to bind really belongs to you. Once confirmed, you can place apps and interactive games you built in your Ryxis Greenhouse knowledge base onto that stream for chat viewers to join. This check is necessary: without verifying ownership, anyone could point our streaming tools at someone else’s channel. We never read your videos, playlists, subscriptions, watch history or analytics; we never read or post comments; and we never publish anything on your behalf (the access is read-only and technically cannot write). We store only that channel ID and title, linked to your account; you can unlink at any time, which deletes that data together with the stored authorization. Note also that live chat messages themselves are read using a public API key — your viewers do not need to authorize any Google permission to take part.

Google Calendar (Google Calendar API): when you enable “schedule sync,” we read your calendar list (calendar names and access levels only, not the contents of any event) so that you can choose which calendar to sync into; and when you press sync, we create, update or delete — in that one calendar you chose — only the events produced by this feature. We do not modify or delete events created by you or by other applications, and we do not read the contents of your other calendars. This access is used solely for this calendar feature.

For user data obtained through Google APIs (including YouTube API Services and Google Workspace APIs), we comply with the Google API Services User Data Policy (including the Limited Use requirements), the YouTube API Services Terms of Service, and Google’s applicable policies. By using YouTube features you also agree to the YouTube Terms of Service (https://www.youtube.com/t/terms); Google’s Privacy Policy is available at https://policies.google.com/privacy.

We do not use data obtained through Google APIs to: sell or transfer it to others, serve advertising of any kind, assess credit or lending, or develop, improve or train generalized AI or machine-learning models.

Except where necessary to provide a feature you requested, with your explicit consent, for security and abuse prevention, or as required by law, we do not share your Google user data with third parties and humans do not access it.

You can revoke the Service’s access to your Google data at any time on your Google account security page: https://myaccount.google.com/permissions

5. Period, region, recipients and methods of use

Period: for as long as the purposes in this policy apply, or the retention period required by applicable law.

Region: your personal data is stored and processed where our servers or those of our processors are located (which may include locations of overseas cloud providers).

Recipients: Vaxal, processors bound by confidentiality obligations that are necessary to provide the Service (e.g. cloud hosting, payments, email delivery), and authorities with lawful jurisdiction.

Methods: processed and used by automated or non-automated means within the scope of the collection purposes.

6. Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, remember your preferences and analyze usage. You can refuse or delete cookies via your browser settings, though some features may not work.

7. Data sharing and disclosure

We do not sell your personal data. We share it only: (1) with your consent; (2) with confidentiality-bound processors necessary to provide the Service; (3) as required by law or by competent/judicial authorities; or (4) to protect the rights, property or safety of Vaxal, users or the public, and to prevent fraud and abuse.

8. Data security

We apply reasonable technical and organizational measures (e.g. encryption in transit and at rest, access control, least-privilege) to protect your personal data, though no internet transmission or storage can be guaranteed to be absolutely secure.

9. Retention and deletion

You can delete content you create in the Service at any time. After you delete or terminate your account, you may export your User Content within a reasonable period (in principle 30 days), after which we delete or de-identify your personal data, except where retention is legally required (consistent with the termination clause of the Terms of Service).

Your Greenhouse knowledge base is stored in standard git format, which you can export and take with you at any time.

10. Your rights and how to exercise them

Under Article 3 of the Personal Data Protection Act, regarding the personal data we hold about you, you may: inquire about or request to review it, request a copy, request supplementation or correction, request that we stop collecting/processing or using it, and request deletion.

You can make a request via the contact details in section 1, and we will handle it in accordance with the law. If you do not provide necessary personal data, you may be unable to use all or part of the Service.

11. Minors

The Service is not primarily directed at minors. If you are under the age of majority, please use the Service with the consent of your legal guardian.

12. Changes to this policy

We may revise this policy due to legal changes or service adjustments. Revisions will be posted on this page with an updated “last updated” date; for material changes we will notify you by appropriate means.

13. Contact us

If you have any questions about this policy or the handling of your personal data, email vaxalnet@gmail.com.